If you prefer to view the firewall rules from the perspective of specific ports, please refer to ports used by Theatre Manager
| Item |
Machine and Purpose |
Subject to PCI |
Virus S/W |
Inbound Port Rules |
Outbound Port Rules |
| 1 |
PostgreSQL server
database |
depends |
no* |
- 5432 from any 192.168.1.x (note: traffic to DB will be using TLS 1.2)
|
- all to 192.168.1.x
- 37 to NTP server
|
| 2 |
Remote Box Office via VPN
(or terminal server) |
yes |
yes* |
|
- all to internet
- 5432 to 192.168.1.2 (Postgres Server)
|
| 3 |
Web Services (TM Listener) |
yes |
no* |
- 443 from 192.168.1.10 (NGINX server)
- 8111 from other TM listeners if they exist
- any from 192.168.1.2 (Postgres server)
|
- any to 192.168.1.10 (NGINX web server)
- 5432 to 192.168.1.2 (Postgres)
- 53 for DNS, MX lookup
- 37 to NTP server
- 443 to
- www2.artsman.com and
- downloads.artsman.com
- 80 to maps.googleapis.com/maps/api/geocode
- 25 (or 465 or 587) to SMTP server (as required)
- 110 to pop server for Facility Mgt
- 443 outgoing to credit card provider
- 443 outgoing to ippos.moneris.com if using a P400 EMV device from Moneris
|
| 4 |
Box Office Workstations |
yes |
yes* |
|
- 80, 443, 8111 to 192.168.1.10 (web server)
- 5432 to 192.168.1.2 (postgres)
- 53 for DNS, MX lookup
- 37 to NTP server
- 443 to
- www2.artsman.com and
- downloads.artsman.com
- 80 to maps.googleapis.com/maps/api/geocode
- 80 to www.google.com/maps/api/staticmap
- 80 to help.theatremanager.com
- 443 outgoing to credit card provider
- 443 outgoing to ippos.moneris.com if using a P400 EMV device from Moneris
|
| 5 |
Ticket Printer |
no |
n/a |
- 10001 from 192.168.1.x (or whatever port the printer is set on
|
|
| 6 |
Web Server (NGINX) |
yes |
yes* |
|
- port 443 to 192.168.1.9 (Web Services TM Listener)
|
| 7 |
Outside of Firewall |
no |
n/a |
- 80,443 from internet
- xxxx from internet or Term Services
|
- forward 80,443 to 192.168.1.10 (NGINX Web Server - which automatically escalates to 443 using TLS 1.2 or later)
- forward xxxx to 192.168.1.4 (Term Server)
|
| 8 |
Internal Wireless Router |
no |
n/a |
|
- specific to 192.168.2.1 as required
|
| 9 |
Venue Lan
computers not handling credit cards
|
no |
yes |
|
|
| 10 |
wireless ticket scanners |
no |
n/a |
|
- Ticket scanning occurs through the internet via tickets.yourvenue.org and port 443. Open ports to allow scanning traffic to the outside of the router
|